Passing files by URL

The rules a file link must satisfy, and the content types each input accepts.

There is no upload endpoint. A file input takes a public HTTPS link, which we fetch, verify and copy into your Morphic project before the run starts. Your CDN stays the origin of your own content, and images, video, audio and documents all use one contract.

RequirementDetail
HTTPSplain http is refused
It serves the filethe response body must be the bytes. A preview or share page — a Drive viewer, a Dropbox landing page, any HTML wrapper — is refused
A public host namehost names only. An IP address, localhost, or a name that resolves to a private address is refused
No credentials in the URLhttps://user:pass@… is refused. A presigned query string is fine, and is never written to our logs
A listed content typethe response's Content-Type must be one of that input's url_content_types
Bytes that matchthe file's first bytes are checked against the type it was served as, before it is kept. A PNG served as a PDF, an HTML page served as JSON, or any ZIP served as a DOCX is refused
Inside max_byteschecked from Content-Length first, then enforced again while the bytes stream
At most 3 redirectsmore than three hops is refused
Valid for the whole fetcha link that expires mid-transfer fails the run
Not emptya link that serves zero bytes is refused
Delivered promptlya host that cannot deliver the whole file inside about 40 seconds is refused, and a run's links together get about 90 seconds

A signed link with a short lifetime is the usual cause of a half-fetched file. Give it at least a few minutes of validity past the moment you start the run.

Content types by input type

The exact list for an input is in its url_content_types. These are the types each input type can be configured to accept.

Input typeContent types
imageimage/png, image/jpeg, image/webp, image/gif, image/tiff, image/avif, image/heic
videovideo/mp4, video/webm, video/quicktime, video/mpeg, video/x-matroska
audioaudio/mpeg, audio/wav, audio/aac, audio/ogg, audio/mp4, audio/webm
documentapplication/pdf, text/plain, text/markdown, text/csv, application/json, and DOCX

Anything not on an input's list is refused. There is no "any file" input type, and an extension is never trusted — what the bytes are is what counts.

Per-run caps

Links and bytes are capped per run across all file inputs together — see Errors & limits.

On this page